Stopping a targeted attack on a Managed Service Provider (MSP) with ThreatDown MDR
ID: 376b75ad-4e6f-58ce-a2b4-6f310c4763d7
STIX ID: report--376b75ad-4e6f-58ce-a2b4-6f310c4763d7
Feed Name: Malwarebytes Blog
In late 2023 ThreatDown MDR discovered and stopped a three-month stealthy malware campaign targeting a European MSP that leveraged living-off-the-land techniques and legitimate remote access/RMM tools (AnyDesk, TeamViewer, ScreenConnect) while attempting to deploy Remcos/AsyncRAT and communicate with known C2 servers; ThreatDown blocked malicious connections, isolated affected endpoints, and recommended re-imaging, password changes, and tighter filtering to remediate the intrusion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
